[Linkpost] Prefixing names with 'secure_' makes agents write more secure code
The graphs are interactive and don't translate well to inline, so the full writeup with figures is in the link.We gave coding agents a three-step synthesis task: build a document management API, then extend it twice. Across conditions we varied the prefix attached to the four initial function names (secure_, safe_, energetic_, lazy_, unsafe_, control). The downstream steps were identical, prefix-neutral prompts. Each task was handed to a fresh agent, with only the codebase as context to influenc...
Read full article →